Commit Graph
22 Commits
Author SHA1 Message Date
austin 55ec39989a Update dependency lucide-react to v1.28.0
renovate/artifacts Artifact file update failure
build-and-publish / build (pull_request) Successful in 1m51s
2026-07-30 09:01:52 +00:00
austin e643062b17 Merge pull request 'A pull request must not touch :latest' (#9) from ci/pr-image-tag into main
build-and-publish / build (push) Successful in 1m31s
2026-07-27 09:58:25 -05:00
austinandClaude Opus 5 5fd5bf940b A pull request must not touch :latest
build-and-publish / build (pull_request) Successful in 1m45s
This runner builds on the host's Docker daemon — the same daemon the live
container runs on — so retagging :latest IS a deployment. Watchtower compares
the running container's image against :latest, sees they differ, and recreates
the container from whatever was just built locally. Gating only the push was
never enough; the build itself was the deploy.

The worse failure is quieter. Reassigning :latest leaves the running
container's old image untagged, and once that image is pruned Watchtower can no
longer read it to compare against:

  Failed to retrieve container image info: No such image: sha256:…
  Unable to update container: no available image info.

bennett-portfolio hit exactly that. It sat on a four-day-old build, failing to
update 720 times in twenty-four hours, reporting healthy the whole time, and had
to be recreated by hand. This repo has the same workflow and the same exposure —
it simply has not been unlucky yet.

A PR now builds pr-<number>, which nothing watches. Trivy scans whatever was
built either way, so a bad Dockerfile or a new CVE still blocks the merge, and
the push step is unchanged — still main-only.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-07-27 09:53:23 -05:00
austin b7cbdd0f29 Merge pull request 'Update bennett platform to v0.1.10' (#8) from renovate/bennett-platform into main
build-and-publish / build (push) Successful in 1m51s
2026-07-26 22:01:41 -05:00
austin 72854bb5fd Update bennett platform to v0.1.10
build-and-publish / build (pull_request) Successful in 1m50s
2026-07-27 02:57:41 +00:00
austinandaustin a13d846311 docs: add CONTRIBUTING guide (#6)
Co-authored-by: austin <[email protected]>
2026-07-23 14:42:09 -05:00
austin f5683c0d31 Merge pull request 'CI: gate the merge on tests' (#5) from ci/gate-merge into main
build-and-publish / build (push) Successful in 1m41s
2026-07-23 13:54:03 -05:00
austinandClaude Opus 4.8 1be8dfd399 CI: gate the merge, not just the image
build-and-publish / build (pull_request) Successful in 2m17s
Run the workflow on pull_request too, so tests + build + Trivy must pass before main can be
merged (branch protection requires this check). Push the image only on a real push to main —
never from a PR. Also standardises the workflow across all apps (three had drifted).

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_01XXKjx7FNyRVAjU8dgB5KhN
2026-07-23 13:54:02 -05:00
austinandClaude Opus 4.8 d570e3579b CI: actually run the tests, and let them gate the image
build-and-publish / build (push) Successful in 1m42s
The image build runs 'mvn -DskipTests' and the workflow was only build -> Trivy -> push, so
no app test has ever run in CI — only Trivy gated a merge. The platform contract tests added
in 0.1.9 were not running either, which defeated their purpose.

They cannot run inside 'docker build' — Testcontainers needs a Docker daemon and a build has
none. Maven runs as a sibling container instead, mounting the workspace volume act_runner
gave this job (matched on GITHUB_WORKSPACE, since it is mounted at the full repo path rather
than at /workspace) and sharing the host network so published test ports resolve as localhost.

Verified on itsthevine before rolling out here: 33 tests ran, and a deliberately failing test
failed the run at the Test step with the registry digest unchanged — no image published.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_01XXKjx7FNyRVAjU8dgB5KhN
2026-07-23 12:20:41 -05:00
austinandClaude Opus 4.8 220b9af34c Restore the dependency upgrades I reverted
build-and-publish / build (push) Successful in 1m20s
The merged Renovate bumps were undone when I rsync'd a local tree over these repos while
pushing the contract tests — that local package.json was a pre-merge backup I had kept so
the PRs would be the source of the versions.

Re-applied and verified from a clean install (rm -rf node_modules package-lock.json &&
npm install && tsc && vite build), which is also what regenerates a lock file consistent
with all the bumps at once.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_01XXKjx7FNyRVAjU8dgB5KhN
2026-07-23 09:56:47 -05:00
austinandClaude Opus 4.8 0c43951672 Inherit the platform contract tests, and extend the shared Renovate preset
build-and-publish / build (push) Successful in 1m18s
PlatformWebContract asserts what this app must do because it is on the platform: an /api
path matching no controller 404s rather than returning the SPA, health is UP, the liveness
and readiness probes exist, and a client-side route forwards to the shell. That first one
shipped broken to six live sites and was found by typing a URL by hand; now it fails a
build instead.

renovate.json is three lines pointing at austin/renovate-config. The rules were copied per
repo, so they matched only by luck and a change was six edits.

Platform 0.1.9.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_01XXKjx7FNyRVAjU8dgB5KhN
2026-07-23 09:46:54 -05:00
austin b1e5a2c321 Merge pull request 'Update dependency typescript to v7' (#3) from renovate/typescript-7.x into main
build-and-publish / build (push) Successful in 1m38s
2026-07-23 08:52:24 -05:00
austin 3a4930027b Merge pull request 'Update dependency lucide-react to v1.26.0' (#2) from renovate/lucide-monorepo into main
build-and-publish / build (push) Successful in 1m42s
2026-07-23 08:51:00 -05:00
austinandClaude Opus 4.8 9230ad1bc4 tsconfig: drop baseUrl, which TypeScript 7 removed
build-and-publish / build (push) Successful in 1m11s
TS7 errors with 'Option baseUrl has been removed'. The paths mapping already points at
./src/*, which resolves relative to this file without it, and TS 5.9 accepts the same
config — so this lands safely ahead of the TypeScript 7 bump.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_01XXKjx7FNyRVAjU8dgB5KhN
2026-07-23 08:50:09 -05:00
austin d83a970166 Update dependency typescript to v7
renovate/artifacts Artifact file update failure
2026-07-23 12:44:24 +00:00
austin 352373b0f3 Merge pull request 'Update bennett platform to v0.1.7' (#1) from renovate/bennett-platform into main
build-and-publish / build (push) Successful in 1m14s
2026-07-23 07:44:24 -05:00
austin 99f7a97572 Update dependency lucide-react to v1.26.0
renovate/artifacts Artifact file update failure
2026-07-23 12:44:23 +00:00
austin 92c921db82 Update bennett platform to v0.1.7 2026-07-23 12:44:22 +00:00
austinandClaude Opus 4.8 8abca06a86 Rebuild on the Bennett platform: Spring Boot + Vite/React
build-and-publish / build (push) Successful in 1m18s
Same site — glass header, bento grid, hero drift, dark mode — with three things fixed
on the way:

- Tailwind and lucide came from CDNs on every page load, and the fonts from Google. All
  are now built in or self-hosted, so the site owes nothing to third parties at runtime.
- The hero and bento photographs were hot-linked from Unsplash. They are re-encoded to
  webp and served from the MinIO bucket with a year-long cache.
- The ministries and labs were hard-coded in the markup, so launching a ministry meant
  editing HTML. They now come from /api/network.

The mobile menu button also opens something now; it did nothing before.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_01XXKjx7FNyRVAjU8dgB5KhN
2026-07-23 07:30:01 -05:00
austinandClaude Opus 4.8 f2be8ce247 Add Docker build + Gitea Actions CI (self-host at reformedwitness.net)
build-and-publish / build (push) Successful in 3s
Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
2026-07-22 12:59:01 -05:00
Austin 48b8b44e6e 2.0 site 2026-02-03 09:21:50 -06:00
Austin a0f968ba4c first commit 2026-02-03 09:21:28 -06:00